THORChain, the decentralized cross‑chain liquidity protocol, has publicly rejected a demand from Bitget CEO Gracy Chen to block a series of wallet addresses that were allegedly used in the exchange’s recent hack. The exchange’s leadership argued that the compromised addresses should be frozen on the THORChain network to prevent further illicit activity, but the protocol’s developers cited its permissionless architecture and the difficulty of retroactively censoring on‑chain activity.
The dispute came to light after a transaction recorded at 03:14 a.m. Eastern Time on September 27 moved 9,999 XRP from an address flagged by Bitget to a wallet that subsequently swapped the XRP for Bitcoin on THORChain. Bitget’s security team identified the source as one of the addresses tied to the breach that resulted in the loss of millions of dollars worth of assets from its platform. In response, Bitget’s CEO issued a public statement urging THORChain to intervene and block the address to protect users and restore confidence.
THORChain’s core developers responded by emphasizing the protocol’s design principles. As a permissionless network, THORChain does not maintain a centralized authority capable of blacklisting or freezing assets. Every transaction is settled by smart contracts that execute automatically based on the state of the blockchain. Introducing a manual blocklist would undermine the trustless nature of the system and set a precedent that could be exploited for political or competitive censorship.
From a technical perspective, implementing address blocking on THORChain would require a fundamental redesign of its consensus mechanism. The protocol relies on a network of independent nodes that validate swaps without a central point of control. Adding a blacklist would necessitate additional on‑chain governance proposals, voting procedures, and potentially new smart‑contract modules, all of which could increase latency and expose new attack vectors.
Security experts note that while the desire to protect users is understandable, the solution may lie in improving monitoring tools and rapid response frameworks rather than attempting to alter the protocol’s immutable rules. Enhanced analytics can flag suspicious patterns, and third‑party services can alert exchanges when compromised addresses attempt to interact with liquidity pools. However, these measures operate outside the core protocol and do not guarantee that illicit swaps will be prevented.
The incident also highlights the broader tension between decentralized finance platforms and centralized exchanges when it comes to post‑incident remediation. Centralized entities like Bitget have the ability to freeze accounts, reverse transactions, and enforce compliance, whereas DeFi protocols must rely on code that cannot be altered retroactively. This fundamental difference often leads to friction, especially when large sums are at stake.
Market participants have reacted with mixed sentiment. Some investors praise THORChain for upholding its permissionless ethos, arguing that any deviation could erode the trust that underpins DeFi. Others express concern that the lack of a protective mechanism may deter institutions from integrating with THORChain, fearing exposure to unchecked malicious activity.
Looking ahead, the THORChain community may explore governance proposals that introduce optional safeguards, such as voluntary opt‑in modules for liquidity providers who wish to limit exposure to flagged addresses. Such an approach would preserve the protocol’s open nature while offering a layer of risk mitigation for those who desire it.
In the meantime, Bitget is expected to continue pursuing off‑chain remedies, including legal action against the perpetrators and strengthening its internal security posture. The exchange has also indicated that it will work with analytics firms to improve the detection of compromised assets moving across multiple blockchain ecosystems.
Ultimately, the episode serves as a reminder that the decentralized finance space still grapples with the challenge of balancing open access with robust security. As cross‑chain swaps become more prevalent, stakeholders across the ecosystem will need to collaborate on standards, monitoring solutions, and best practices that protect users without compromising the foundational principles of permissionless finance.
